Security researcher Patrick Wardle has published a proof of concept showing that malware already running as the logged-in macOS user can quietly take over Meta's Muse assistant by redirecting where it sends dictated prompts. The mechanism is an undocumented application preference, endo_voyager_dictation_endpoint, which any process running as that user can repoint at an attacker-controlled address without additional permissions. From there Wardle demonstrated three consequences: reading what the user dictated, injecting extra instructions that Muse treats as trusted, and capturing the account token — which matters because a Muse account can be signed in on multiple devices, so a stolen token lets the attacker direct the assistant beyond the compromised Mac. Muse is the personal AI agent Meta launched this month in the United States; it works across files, email, messages, the calendar, shopping and smart-home apps, using whatever access the user grants, and Wardle's argument is that this is exactly why it is a target: macOS Data Protection normally limits what malware can reach, and steering a signed app with broad permissions bypasses that limit without triggering security tooling, because the commands come from an app the user trusted. He also notes a remote attacker could deliver it through a ClickFix-style trick. Wardle's advice is blunt: do not install Muse.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-09-23 |
| Source | The Register |
| Reliability | Tier 3 |